CVE detail
CVE-2012-0954 — CVE-2012-0954
Published 2012-06-19 · Modified 2026-06-16 · Vendor debian · Product advanced_package_tool · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0221
EPSS probability
exploitation probability, 30d
81.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3587.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References